A data protection impact assessment, or DPIA, is the structured exercise GDPR requires before processing likely to create high risk for individuals: describe the processing, assess necessity and proportionality, identify risks and set mitigations. Regulators expect one for things like large-scale monitoring of a publicly accessible area.
Workplace projects that commonly trigger a DPIA include occupancy sensing, camera-based systems and any monitoring that could read as employee surveillance. Booking-based systems generally sit at the low-risk end, one reason many organisations prefer booking data over cameras for utilisation measurement.